Executive brief
The Bulk SEO Image plugin for WordPress, which helps automate image optimization for search engines, contains a security flaw that allows unauthorized changes to website content. By tricking a site administrator into clicking a malicious link, an attacker can automatically overwrite the alternative (ALT) text for every image on the website. This can damage the site's search engine rankings and disrupt accessibility features for users.
Technical details
The Bulk SEO Image plugin for WordPress (up to version 1.1) is vulnerable to Cross-Site Request Forgery (CSRF) due to missing nonce validation in the BulkSeoImage() settings page handler. The handler dispatches to launchbulk() and BulkSeoImageGo() without verifying a security nonce when the 'bulkseoimage' POST parameter is present. An unauthenticated attacker can exploit this by inducing a logged-in administrator to visit a malicious URL. Successful exploitation allows the attacker to bulk-overwrite the '_wp_attachment_image_alt' post meta for all images attached to published posts and pages.
Affected products
- seo_tools Bulk SEO Image up to and including 1.1
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory
References
- https://plugins.trac.wordpress.org/browser/bulk-seo-image/tags/1.1/bulk-seo-image.php
- https://plugins.trac.wordpress.org/browser/bulk-seo-image/tags/1.1/bulk-seo-image.php
- https://plugins.trac.wordpress.org/browser/bulk-seo-image/tags/1.1/bulk-seo-image.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/ef176a6c-33d1-45d6-8a1d-3df1e8eb2170?source=cve